共声岛 EchoBay

Security and trust

Vulnerability Disclosure Policy

Thank you for helping EchoBay protect its users and services. If you believe you found a security issue, stay within these boundaries, stop after obtaining the minimum proof, and report it privately through the dedicated security mailbox.

Report a security issue privately

Testing scope

This policy covers only the following public services operated by EchoBay:

  • echobay.club
  • app.echobay.club
  • api.echobay.club
  • downloads.echobay.club

Testing boundaries

  • Do not perform Denial-of-service attacks (DDoS/DoS), high-volume load testing, or other activity that harms availability.
  • Do not use social engineering, phishing, impersonation, harassment, or deception against EchoBay users, staff, or suppliers.
  • Do not establish persistence, install a backdoor, retain unauthorized access, or continue access after verification.
  • Do not destroy or alter data, including deleting, writing, moving, or corrupting it.
  • Do not access another user's data. If you see it accidentally, stop immediately and do not download, copy, retain, or share it.

How to report

Stop once you have confirmed the issue, retain only the minimum proof, and report it privately to security@echobay.club. Do not disclose it publicly or include unrelated personal data, credentials, or complete datasets.

  • Identify the affected domain, path, feature, and the impact you observed.
  • Provide the fewest safe reproduction steps. Redact sensitive values and include only the fragment needed to understand the issue.
  • Include contact details you want us to use for follow-up.

Response targets

After the dedicated security mailbox receives a complete, actionable report, we aim to:

Within 3 business days
Acknowledge the report and provide a tracking status.
Within 7 days
Complete an initial severity classification and outline next steps.
Immediate containment
Prioritize isolation and emergency containment for serious active exploitation.